<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif;">
<div style="font-family: Calibri, sans-serif;">Hi,</div>
<div style="font-family: Calibri, sans-serif;"><br>
</div>
<div style="font-family: Calibri, sans-serif;">We have a department that currently has a license for Zoom a cloud based video conferencing and communications and they would like to integrate with our IdP. &nbsp;Does anyone have any experiencing integrating with
 them?</div>
<div style="font-family: Calibri, sans-serif;"><br>
</div>
<div style="font-family: Calibri, sans-serif;">After reading the documentation and speaking with their support I ran into a couple of issues.</div>
<div style="font-family: Calibri, sans-serif;"><br>
</div>
<div style="font-family: Calibri, sans-serif;">They do not support encrypted assertions. &nbsp;From what I&#8217;ve seen there have been a lot of vendor applications that have their own SAML implementations that do not support encrypted assertions. &nbsp;So I guess this is
 more of a comment than a question/issues.</div>
<div style="font-family: Calibri, sans-serif;"><br>
</div>
<div style="font-family: Calibri, sans-serif;">This is my stupid question, but looking at the metadata they provided it appears that it does not contain any certificate information. &nbsp;Their support provided the following &quot;We do receive iDP cert but we not require
 SP cert as we do not sign requests and response sent to the Identity Provider today. The SSO sign-in page is transmitted over https only.&#8221; &nbsp;The schema allows for 0 KeyDescriptors, but I have never run into a scenario where a SP had 0. &nbsp;Does anyone have any
 experience working with this? &nbsp;I am not even sure if this will work and if signing isn&#8217;t enabled it just doesn&#8217;t seem secure. &nbsp;The metadata I am referring to is below.</div>
<div style="font-family: Calibri, sans-serif;"><br>
</div>
<div>
<p style="margin: 0px;">&lt;?xml version=&quot;1.0&quot; encoding=&quot;UTF-8&quot;?&gt;&lt;md:EntityDescriptor xmlns:md=&quot;urn:oasis:names:tc:SAML:2.0:metadata&quot; entityID=&quot;ucla.zoom.us&quot;&gt;&lt;md:SPSSODescriptor AuthnRequestsSigned=&quot;false&quot; WantAssertionsSigned=&quot;true&quot; protocolSupportEnumeration=&quot;urn:oasis:names:tc:SAML:2.0:protocol&quot;&gt;&lt;md:SingleLogoutService
 Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect&quot; Location=&quot;<a href="https://ucla.zoom.us/saml/SingleLogout">https://ucla.zoom.us/saml/SingleLogout</a>&quot; ResponseLocation=&quot;<a href="https://ucla.zoom.us/saml/SingleLogout">https://ucla.zoom.us/saml/SingleLogout</a>&quot;/&gt;&lt;md:SingleLogoutService
 Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&quot; Location=&quot;<a href="https://ucla.zoom.us/saml/SingleLogout">https://ucla.zoom.us/saml/SingleLogout</a>&quot; ResponseLocation=&quot;<a href="https://ucla.zoom.us/saml/SingleLogout">https://ucla.zoom.us/saml/SingleLogout</a>&quot;/&gt;&lt;md:NameIDFormat&gt;urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress&lt;/md:NameIDFormat&gt;&lt;md:NameIDFormat&gt;urn:oasis:names:tc:SAML:2.0:nameid-format:transient&lt;/md:NameIDFormat&gt;&lt;md:NameIDFormat&gt;urn:oasis:names:tc:SAML:2.0:nameid-format:persistent&lt;/md:NameIDFormat&gt;&lt;md:NameIDFormat&gt;urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified&lt;/md:NameIDFormat&gt;&lt;md:NameIDFormat&gt;urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName&lt;/md:NameIDFormat&gt;&lt;md:AssertionConsumerService
 Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect&quot; Location=&quot;<a href="https://ucla.zoom.us/saml/SSO">https://ucla.zoom.us/saml/SSO</a>&quot; index=&quot;0&quot; isDefault=&quot;true&quot;/&gt;&lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&quot;
 Location=&quot;<a href="https://ucla.zoom.us/saml/SSO">https://ucla.zoom.us/saml/SSO</a>&quot; index=&quot;1&quot;/&gt;&lt;/md:SPSSODescriptor&gt;&lt;/md:EntityDescriptor&gt;</p>
<p style="margin: 0px;"><br>
</p>
<p style="margin: 0px;">Thanks</p>
<p style="margin: 0px;"><br>
</p>
<p style="margin: 0px;">Warren</p>
</div>
</body>
</html>